5
CVSSv2

CVE-2011-3580

Published: 30/09/2011 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

IceWarp WebMail in IceWarp Mail Server prior to 10.3.3 allows remote malicious users to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function.

Vulnerable Product Search on Vulmon Subscribe to Product

icewarp mail server 10.0.7

icewarp mail server 10.0.8

icewarp mail server 10.0.3

icewarp mail server 10.0.4

icewarp mail server 10.2.1

icewarp mail server 10.2.2

icewarp mail server 9.4.1

icewarp mail server 9.4.0

icewarp mail server 10.1.2

icewarp mail server 10.1.3

icewarp mail server 9.3.1

icewarp mail server 9.3.2

icewarp mail server 10.1.1

icewarp mail server 10.3.0

icewarp mail server 9.3.0

icewarp mail server 9.4.2

icewarp mail server 10.3.1

icewarp mail server 10.1.4

icewarp mail server 10.2.0

icewarp mail server

Exploits

IceWarp Mail Server versions 1032 and below suffer from XML external entity injection and PHP information disclosure vulnerabilities ...